[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRByQXyxEYYCxbiNz7YhEGQpSGVZu-djdBnXKd4atszw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"a6d2890a-ed66-4e08-a6f0-638a373b1109","wazza-phishing-kit-bypasses-detection-to-harvest-credentials-across-critical-sectors","3b427ccb-225c-4e39-93c7-206d7b91641f","Wazza Phishing Kit Bypasses Detection to Harvest Credentials Across Critical Sectors","The Wazza phishing kit represents a significant evolution in credential harvesting attacks, using multi-stage routing infrastructure to filter out security scanners and automated traffic before delivering its malicious Adobe-themed Device Code phishing payload. By impersonating a trusted brand like Adobe and targeting high-value sectors — banking, government, and manufacturing — attackers maximize the likelihood of capturing privileged credentials. The Device Code flow abuse is particularly dangerous because it can bypass multi-factor authentication by tricking users into authorizing attacker-controlled sessions. This matters because compromised credentials in these sectors can lead to large-scale data breaches, regulatory violations, and disruption of critical infrastructure.","**Immediate actions:**\n- Block or alert on Device Code OAuth flow authentication requests originating from unmanaged or unexpected devices.\n- Deploy anti-phishing email filtering rules that flag Adobe-branded login pages hosted outside of legitimate Adobe domains.\n- Enforce phishing-resistant MFA (e.g., FIDO2\u002Fpasskeys) across all user accounts, especially in banking and government environments.\n\n**Long-term improvements:**\n- Implement Conditional Access policies that restrict Device Code flow to only approved, managed devices.\n- Conduct regular security awareness training that specifically covers phishing lure tactics, including trusted-brand impersonation and OAuth abuse.\n- Establish a formal threat intelligence program to ingest and act on emerging phishing kit indicators of compromise (IOCs).\n\n**Detection measures:**\n- Monitor authentication logs for anomalous Device Code grant activity, particularly from unfamiliar IP ranges or geographies.\n- Deploy browser isolation or URL sandboxing to intercept and analyze multi-stage redirect chains before users reach phishing payloads.\n- Set up alerts for credential submission events to domains not on an approved allowlist.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 9 – Email and Web Browser Protections","CIS Control 14 – Security Awareness and Skills Training","CIS Control 16 – Application Software Security","NIST SP 800-63B – Digital Identity Guidelines (Phishing-Resistant MFA)","NIST AC-17 – Remote Access Controls","NIST SI-3 – Malicious Code Protection","NIST IR-4 – Incident Handling","MITRE ATT&CK T1566 – Phishing","MITRE ATT&CK T1528 – Steal Application Access Token (Device Code Flow)","GDPR Article 32 – Security of Processing","NIST CSF DE.CM-1 – Network Monitoring","ITIL – Continual Service Improvement (Security Training Cadence)","published","2026-10-08T12:20:38.022303+00:00","2026-10-08T12:20:37.933+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fwazza-phishkit-targets-banking.html","wazza-phishkit-targets-banking-government-and-manufacturing-across-the-us-eu-and-e8a1c9","Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":45,"name":46,"slug":47,"description":48,"color":49},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[51],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"ad9ad71a-ab06-4a6e-a172-192c16d068ed","2026-10-08","afternoon","ThreatNoir Afternoon Brief — October 8","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-10-08\u002Fthreatnoir-afternoon-brief-2026-10-08.mp3"]